Repository health

A repository score that shows its reasoning.

GSkout's overall health score is not simply the dependency score under another name. It combines several supported repository signals and exposes their contribution.

Security

Known vulnerabilities and supported source-security findings influence repository health, with critical high-confidence findings receiving the strongest impact.

Dependencies

Dependency condition reflects evaluated package vulnerabilities, maintenance status and freshness without pretending unresolved versions are safe.

Coverage

Coverage represents how much of GSkout's supported repository analysis scope was successfully loaded and evaluated.

Analysis quality

Parsing success and confidence in supported source inspection contribute to how strongly the final score should be interpreted.

Why critical flows can cap the score.

A repository with strong dependency freshness and full analysis coverage should not receive a reassuring overall score when GSkout finds a high-confidence critical path such as request-controlled input reaching shell execution.

Critical confirmed flows can therefore impose a stronger score penalty or cap than maintenance warnings or normal dependency age.

A score is a summary, not a security guarantee.

Repository health should be used as a navigation signal. Investigation still happens at finding, dependency and file level. Unsupported vulnerabilities or runtime issues may exist outside the score's analysis scope.